- State
- CA
- Covered entity type
- Healthcare Provider
- Individuals affected
- 800
- Business associate present
- No
- Type of breach
- Unauthorized Access/Disclosure
- Location of breached information
- Other
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
On June 30, 2017, the covered entity (CE), White Blossom Care Center reported that its former employees impermissibly accessed and copied its residents’ protected health information (PHI) while employed at the facility. The breached electronic PHI included names, dates of birth, social security numbers, telephone numbers, health insurance information, and medical record numbers. The CE provided breach notification to HHS, 791 affected individuals, and the media and posted substitute notice on its website. It also offered identity theft provision services to affected individuals. In response to the breach, the CE immediately contacted the FBI and San Jose Police Department and reported both former employees to the California Department of Public Health Licensing Division It also worked with Mandiant, a digital forensics firm, to ensure internal safeguards were implemented to restrict patient’s PHI only to authorized employees, revised its policies and procedures, and retrained workforce members. The CE provided OCR with additional documentation including its HIPAA Notice of Privacy Practices Policy, as relevant to this breach investigation. OCR obtained assurances that the CE implemented the corrective actions listed above.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.